Companies House BLUNDER! đŸ˜±

BlackBeltBarrister
BlackBeltBarrister‱Mar 16, 2026

Why It Matters

The flaw jeopardizes corporate data integrity and erodes trust in government‑run digital services, prompting immediate remediation and broader reforms in public‑sector cybersecurity.

Key Takeaways

  • ‱Companies House exposed critical authentication flaw in public portal.
  • ‱Experts label vulnerability as “schoolboy error” and “scandalous incompetence.”
  • ‱Lack of two‑factor verification lets attackers hijack company records.
  • ‱Reviewers urge immediate site shutdown until proper fix implemented.
  • ‱Incident highlights systemic weaknesses in UK government digital infrastructure.

Summary

The video spotlights a serious security breach at Companies House, the UK’s official register of corporate entities. A flaw in the portal’s authentication logic allows a user’s account to be linked to any company without requiring a valid two‑factor authentication token, effectively exposing sensitive corporate data.

Industry veterans – an IT specialist with 35 years of experience, a former software developer, and several security analysts – condemn the oversight as a “schoolboy error” and “scandalous incompetence.” They explain that the system merely checks whether a token was sent, not whether it was completed, and that the vulnerability should have been caught during testing. One expert recommends disabling the site until a robust fix is deployed.

The commentators quote each other sharply: Chris BS calls the situation “a horror show of stupidity,” Decadence calls it “wild vulnerability,” and Ian labels the government’s digital services “a complete shambles.” Another veteran likens the fiasco to the infamous COVID‑tracking app built on an Office 97 spreadsheet, underscoring a pattern of neglect.

The breach threatens business confidence, potentially allowing malicious actors to alter or view company filings. It underscores the urgent need for the UK government to overhaul its digital procurement, testing, and security practices, and it raises questions about regulatory oversight of critical public‑sector IT systems.

Original Description

Discount for Incogni: https://incogni.com/blackbelt
Discounts and Freebies (via affiliate and/or referral links):
4 months free for NordVPN: https://nordvpn.com/bbb
Protect your identity with an exclusive discount on NordProtect at https://nordprotect.com/barrister. Includes 30-day money-back guarantee.
More:
IMPORTANT DISCLAIMER:
I'm a Barrister of England and Wales.
Videos for educational guidance only, Always seek advice before taking action. Videos on my channel are not legal advice and should not be taken as such. I accept no liability for any reliance placed upon the content of these videos or references, therein. Description may contain affiliate or sponsored links, for which we may receive commissions or payment.

Comments

Want to join the conversation?

Loading comments...